Supply-chain threat intelligence
Risk score
92
Indexed incident for lib-1779997093-yjeeqn (pypi).
-= Per source details. Do not edit below this line.=-
During installation, the package opens a reverse shell
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-05-my-test-package-2025-xyz
Reasons (based on the campaign):
The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.
The package overrides the install command in setup.py to execute malicious code during installation.
Affected versions
Indicators
Timeline